Skip to main content
Category: Contracting & Acquisition

Contract Data Requirements List

Also known as:
Simply put

A Contract Data Requirements List (CDRL) is a Department of Defense document that lists all the data items a contractor must deliver to the government during the performance of a contract. These deliverables can include items such as technical reports and other data products. The CDRL becomes part of the contract and tells the contractor what data must be provided and in what form.

Formal definition

The CDRL is the authorized, standardized list identifying the data deliverables a contractor is required to provide to the government under a DoD contract. It generally serves as the standard format for identifying potential data requirements in a solicitation and deliverable data requirements in the resulting contract, forming part of the contract in conjunction with applicable Data Item Descriptions (DIDs), which specify the content and format of each listed data item. Note that this entry describes the CDRL concept as reflected in the cited evidence; it does not cover the specific form number, preparation procedures, or agency-specific tailoring, which the reader should verify against current authoritative DoD acquisition guidance.

Why it matters

The CDRL is the mechanism that transforms a government data need into an enforceable contractual obligation. Because it becomes part of the contract, the CDRL is what makes a contractor legally accountable for delivering specified data items in a defined form. For compliance officers and contracting personnel, this matters because data deliverables often carry security and handling implications: a technical report or other data product delivered under a CDRL may contain or constitute Controlled Unclassified Information (CUI), which can trigger safeguarding and marking obligations separate from the CDRL itself. The CDRL identifies what must be delivered; it does not by itself establish the full scope of how that data must be protected, so readers should not treat a CDRL as a substitute for reviewing applicable security clauses and CUI requirements.

Misunderstanding the relationship between the CDRL and the Data Item Descriptions (DIDs) is a common and consequential error. The CDRL lists the required data items, while the applicable DIDs specify the content and format of each item; the two work together, and neither alone fully defines a deliverable. Treating the CDRL as if it stood in for the detailed content requirements of a DID, or vice versa, can lead to non-conforming deliverables and contractual disputes. Because the evidence digest does not establish specific form numbers, preparation procedures, or tailoring rules, practitioners should confirm those details against current authoritative DoD acquisition guidance rather than relying on general summaries.

Properly constructed CDRLs also support downstream compliance and oversight activities. Clear identification of data deliverables gives authorizing officials, auditors, and program personnel a defined basis for verifying that required information has been provided in the correct form. Ambiguity or omission at the CDRL stage tends to propagate into contract performance problems, which is why accuracy in identifying data requirements at solicitation and contract award is generally emphasized in DoD acquisition practice.

Who it's relevant to

Government Contractors and Program Teams
Contractors performing under DoD contracts rely on the CDRL to understand exactly which data items they are obligated to deliver and in what form. Because the CDRL becomes part of the contract and is generally linked to applicable DIDs, contractor teams should review both together to ensure deliverables meet the required content and format, and should confirm preparation specifics against current authoritative guidance.
Contracting and Acquisition Personnel
Contracting officers and acquisition staff use the CDRL as the standard format for identifying potential data requirements in a solicitation and deliverable data requirements in the resulting contract. Accurate identification of data requirements at this stage supports enforceable, unambiguous deliverable obligations during contract performance.
Compliance Officers and Information System Security Managers
Because data items delivered under a CDRL may include or constitute Controlled Unclassified Information (CUI), compliance and security personnel should assess deliverables against applicable safeguarding, marking, and handling obligations. The CDRL identifies what is to be delivered but does not by itself define the full protection requirements, which must be confirmed under the relevant security clauses and CUI rules.
Auditors and Oversight Personnel
Auditors and program oversight staff can use the CDRL as a defined basis for verifying that required data deliverables have been provided in the correct form. Clarity in the CDRL supports reliable verification, while omissions or ambiguity can complicate assessment of contract performance.

Inside CDRL

DD Form 1423
The standard form used to document each Contract Data Requirements List (CDRL) item, capturing the specifics of a required deliverable data item and its associated instructions.
Data Item Description (DID) Reference
A pointer to the Data Item Description that defines the content, format, and preparation requirements for the deliverable, ensuring the government and contractor share a common understanding of what is expected.
Deliverable Identification and Title
The unique CDRL sequence number and descriptive title identifying each individual data deliverable required under the contract.
Submission and Frequency Requirements
The instructions specifying when and how often the deliverable must be submitted, including delivery dates, recurring schedules, or event-driven triggers.
Distribution and Addressee Information
Designation of the recipients, distribution statements, and any handling or marking requirements applicable to the deliverable, which may include protections for Controlled Unclassified Information (CUI) where the underlying data warrants it.
Inspection and Acceptance Criteria
The basis on which the government reviews, approves, or rejects a submitted deliverable, tying acceptance back to the requirements referenced in the applicable DID.

Common questions

Answers to the questions practitioners most commonly ask about CDRL.

Is a CDRL the same thing as the actual data or deliverable the government receives?
No. A CDRL is not the deliverable itself; it is the contractual list and specification of the data deliverables required under a contract. Each line item on the CDRL identifies a required data product and points to the governing Data Item Description (DID) or other requirement that defines its content and format. Confusing the CDRL (the requirement) with the submitted data (the fulfillment of that requirement) is a common error. Readers should verify specific formatting, content, and acceptance criteria against the applicable DID and the contract's terms.
Does listing a document on a CDRL automatically make it a compliance or cybersecurity artifact?
Not necessarily. A CDRL establishes a contractual obligation to deliver specified data, but inclusion on a CDRL does not by itself determine the security, classification, or compliance treatment of that data. Whether a deliverable involves Controlled Unclassified Information (CUI), classified material, or other protected categories depends on the nature of the data and the applicable safeguarding requirements, not on the CDRL entry alone. Contractual delivery of a document is distinct from meeting any underlying security or compliance requirement, and readers should confirm handling obligations against the contract and current authoritative sources.
Where in a contract are CDRLs typically found and how are they numbered?
CDRLs are generally documented on a standardized form associated with the contract and are commonly referenced by sequential line item identifiers. The specific placement and numbering conventions can vary by contract and issuing organization, so the reader should confirm the exact structure, form, and identifiers against the individual contract's terms rather than assuming a uniform layout across programs.
How does a CDRL relate to a Data Item Description (DID)?
A CDRL line item typically references a DID or another cited requirement that defines the content, format, and preparation instructions for the deliverable. The CDRL states what is due, when, to whom, and in what quantity, while the referenced DID or requirement describes how the deliverable should be prepared. When a DID is tailored, the tailoring should be reflected in the CDRL. Confirm the applicable DID and any tailoring instructions in the specific contract.
What delivery details should a CDRL line item specify?
A CDRL line item generally specifies elements such as the required deliverable, the governing requirement or DID, the frequency or timing of delivery, the recipients or distribution, and quantity or format expectations. Exact fields and expectations depend on the contract and the issuing organization, so readers should verify the required delivery attributes and acceptance criteria against the specific contract and any incorporated instructions.
How should a contractor manage changes to CDRL requirements during performance?
Changes to CDRL requirements are typically handled through the contract's established modification and change processes, and unilateral deviation from a CDRL's stated requirements can create compliance and acceptance risk. If delivery obligations, referenced requirements, or tailoring need to change, those changes should be reflected through the appropriate contractual mechanism. Contractors should confirm the governing change procedures and current requirements with the contracting authority and against the contract's terms.

Common misconceptions

A CDRL is itself a cybersecurity compliance requirement or control.
A CDRL is a contractual mechanism for identifying and scheduling data deliverables; it does not by itself impose security controls. Cybersecurity obligations generally arise from the underlying contract clauses, referenced frameworks, or DIDs, and readers should verify the specific requirements against the current authoritative contract text.
The CDRL and the Data Item Description (DID) are the same thing.
They are distinct. The DID defines the content and format of a deliverable, while the CDRL (documented on the DD Form 1423) identifies which deliverables are actually required for a given contract and specifies delivery, distribution, and acceptance details.
Once listed on a CDRL, a deliverable's requirements are fixed for the life of the contract.
CDRL items can be modified through contract action, and delivery schedules, distribution, or referenced DIDs may change. Practitioners should confirm the currently applicable CDRL requirements rather than relying on an earlier version.

Best practices

Cross-reference each CDRL item against its cited Data Item Description to confirm the expected content, format, and preparation instructions before preparing a deliverable.
Track submission dates, frequencies, and event-driven triggers for every CDRL line item to avoid missed or late deliverables that could affect contract acceptance.
Verify distribution statements, addressees, and handling requirements for each deliverable, and apply appropriate protections where the data involves Controlled Unclassified Information (CUI).
Confirm the inspection and acceptance criteria in advance so deliverables are prepared to meet the government's basis for approval on first submission.
Treat CDRL requirements as subject to change through contract modification, and re-validate the current DD Form 1423 entries whenever contract actions occur.
Do not assume a CDRL deliverable satisfies cybersecurity compliance obligations on its own; confirm applicable security requirements against the governing contract clauses and current official sources.